Installer package for Theme Ultimate Button Controller.
45%
Total Score
unhealthy
Risky: no recent repository activity, no license file, and unclear package-to-repository linkage.
The manifest declares a proprietary license, but no license file is present in either the package or repository. This leaves the terms less transparent for downstream users.
The artifact and linked repository each contain only composer.json, providing little evidence of implementation, documentation, or release structure. The minimal footprint is a material transparency concern for a dependency.
The package is 178 days old with only two releases, both published on the same day, so there is not yet a meaningful long-term maintenance record.
The repository recorded zero commits and zero active maintainers in the last three months. With only two releases, this provides weak evidence of continuing maintenance.
The linked repository name does not match the package and its README does not mention the package. That makes the package-to-source relationship unclear rather than directly demonstrating that the repository belongs to this release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
theme-ultimate/repository-license Version ^1.0 | — | — |
theme-ultimate/theme-ultimate-button-controller Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.